


Privacy & Data Protection
PRIVACY & DATA PROTECTION
Privacy and Data Protection are interrelated concepts that involve complex statutory, regulatory and common law requirements and restrictions. Privacy and data breaches – whether accidental or intentional – are frequent front-page news stories that damage corporate reputations and have led to an increasing number of class action lawsuits. Our privacy and data protection lawyers help clients examine the impact of privacy and data protection laws and regulatory requirements upon their businesses and implement measures to reduce risks.
Canada has a complex network of laws governing privacy and data protection compliance, including private-sector, health-sector and public sector statutes, sector-specific privacy obligations, statutory privacy torts, and evolving common law torts such as “intrusion upon seclusion” and “publicity given to private life.” To provide support to our client, our lawyers routinely prepare and adopt practices and procedures that ensure compliance We advise clients on establishing a comprehensive privacy compliance infrastructure, so that they can reduce the risk of privacy complaints, investigations by privacy commissioners and other regulatory bodies, and privacy-related litigation. An effective compliance infrastructure can also help clients to mitigate the damage of any risks that may materialize.
Our lawyers regularly develop organizational and employee privacy policies and function-specific documents, such as Internet privacy policies, acceptable use policies, and cookies policies. Among other things, McMillan’s data privacy lawyers provide guidance on the application of privacy laws; draft and review privacy policies, consent provisions and information collection procedures; advise on cases of privacy or security breaches; advise on issues related to cross-border transfers of information, including cloud computing; represent clients in privacy-related litigation; and CASL compliance.
Workplace privacy also presents unique issues and challenges. The sheer volume of personal employee information companies handle is just one of the reasons why privacy laws in the workplace are taking centre stage of late. Another emergent workplace privacy issue concerns medical privacy laws in the workplace, which have come to the fore as businesses navigate the legalities of workplace drug testing since Canada legalized marijuana and COVID testing came into play.
McMillan’s workplace privacy lawyers draft and review employee privacy policies, and advise corporations on the application of privacy laws, privacy issues related to searching employees and their property, collection of biometric information, privacy issues unique to unionized workforces, and more.
McMillan’s team also has valuable experience interpreting and applying Canada’s Anti-Spam Legislation (CASL) across organizations, reviewing CASL compliance and training client teams, and dealing with the CRTC and the Privacy Commissioner on CASL compliance matters. Our expertise extends to publication of a legal text, Internet Law Essentials: Canada’s Anti-Spam Law.
Essentially we help clients understand how they can balance compliance with innovation, employer rights, and business needs.
Cybersecurity is no longer solely an issue for IT or technical staff. An effective plan to protect the organization against cyber threats requires insight into both the technical threats and the many and varied ways in which those threats can manifest in personal, physical, and financial damage. Understanding and responding effectively to those threats requires a comprehensive understanding of legal and regulatory obligations and risks, all of which are rapidly evolving.
Among other things, McMillan’s cybersecurity lawyers draft security and data protection policies and protocols; advise on compliance with applicable privacy laws and other legislation; educate managers and directors on the risks associated with a data breach; prepare and implement a notice strategy to respond to data breaches; advise on dealing with the public and regulators following a breach; and assist with internal investigations and obtaining court orders for timely disclosure of necessary information from third parties.
Although organizations may use their best efforts to develop and implement policies and procedures to comply with Canada’s complex and rapidly evolving privacy and data protection regime, disputes regarding breach of privacy and mishandling of personal information are often unavoidable. McMillan helps organizations manage the risk of being drawn into litigation through, for example, inadvertent disclosure of customer information, employee misconduct, or even external hacking of their information systems.
The importance of an immediate and effective response is underscored by the recent wave of reported class actions relating to privacy and data breaches, many of which allege that the organization did not promptly notify individuals who were at risk of harm.
McMillan’s Privacy Group is experienced at resolving disputes in a client-focused way. We pair specialized privacy expertise with McMillan’s renowned Litigation Group to provide a comprehensive team that can advise and represent clients in all types of privacy litigation.
Primary Contacts
View All ContactsDeals and Cases
Downloads
INSIGHTS (118 Posts)
Reporting and Recording Breaches of Security Safeguards – The OPC releases new resources for businesses
Sep 28, 2020
×
COVID-19 Realities Push Ontario Government to Launch Public Consultation to Improve the Province’s Privacy Laws
Aug 19, 2020
×
Global Privacy Authorities Remind Video Teleconferencing Companies of Privacy Expectations
Jul 29, 2020
×
Supreme Court of Canada Affirms the Genetic Non-Discrimination Act, Weighing Autonomy, Privacy, and Accessibility of Insurance
Jul 22, 2020
×
Significant Expansion of Ontario’s Personal Health Information Protections amid COVID-19: What you need to know
Jul 15, 2020
×
As the “New NAFTA” Approaches Ratification, Regulated Foreign Entities Should Anticipate Stricter Record-Keeping Requirements
Feb 25, 2020
×
New Transparency Requirements: Private Companies in British Columbia Now Required to Collect and Disclose Shareholder Information
Jan 31, 2020
×
Under the Influence: The Canadian Competition Bureau’s Stand on Misleading Product Endorsements
Dec 30, 2019
×
One-Year Anniversary of Mandatory Data Breach Reporting: Lessons the OPC Has Learned and What Businesses Need to Know
Nov 11, 2019
×
Is Data Residency Coming to Canada? The OPC Signals a Major Change to its Policy Position on Transborder Dataflows
Apr 15, 2019
×
Financial Institutions: OSFI’s Heightened Cyber Security Incident Reporting Obligations Now In Effect
Apr 8, 2019
×
OSFI Boots Up Cyber Safety with its New Advisory on Technology and Cyber Security Incident Reporting
Feb 6, 2019
×
The Privacy Commissioner’s Guide to Protecting Personal Information in Cannabis Transactions
Jan 30, 2019
×
Is your Privilege Protected? Ontario Court Revisits Doctrine of “Implied Waiver of Privilege” in Recent Decision
Details
Aug 23, 2018
×
PIPEDA’s Breach Reporting Requirements Finalized, to Come Into Force November 1, 2018
Details
May 15, 2018
×
BC Court of Appeal Rules Absolute Privilege Precludes Claim for Breach of Privacy
Details
Mar 8, 2018
×
Sneak Peek at PIPEDA’s Breach Reporting Requirements – Proposed Regulations Released for Comment
Details
Sep 8, 2017
×
Server Location Not Definitive in Determining Jurisdiction Over Foreign Defendant
Details
Aug 31, 2017
×
Supreme Court of Canada Turns the Other Cheek: Facebook’s “Terms and Conditions” – Forum Selection Clause Unenforceable
Details
Jun 29, 2017
×
The tides are changing for cyber regulation, and you may need to take action in order to stay afloat
Details
Apr 5, 2017
×
We’ve Overpaid, Now What? OLRB Confirms Employers’ Obligations in Addressing Pension Overpayments
Details
Mar 3, 2017
×
CSA Provides Cybersecurity Risk Disclosure Guidance and Best Practices for Reporting Issuers
Details
Jan 6, 2017
×
Privilege wins out over Document Production Requests, Orders and FOI Legislation – SCC Confirms Status of Solicitor-Client Privilege and Litigation Privilege
Details
Nov 30, 2016
×
Privacy Alert: Proliferation of Access Requests as New Tools Automate Request Generation and Distribution
Details
Jun 23, 2016
×
Safeguarding Data Transfers of Federally Regulated Entities: Within Canada and Beyond
Details
Apr 26, 2016
×
Decrypting the iPhone – Everybody’s Got Something to Hide, Except Me and My Monkey
Details
Mar 10, 2016
×
Can you keep a secret? The courts recognize a new tort for public disclosure of private facts
Details
Feb 1, 2016
×
Bring Your Own Device (“BYOD”) Programs: Strategic Considerations to Reconcile Security and Privacy Issues
Details
Nov 10, 2015
×
Security Breach Implicating Personal Information: Which Injuries are Compensable?
Details
Sep 15, 2015
×
Shining Light in Dark Places: GPEN Sweep Targets Children’s Mobile Applications and Websites
Details
Sep 13, 2015
×
Online Behavioural Advertising: An Update for Advertisers, Ad Networks and Agencies
Details
Aug 10, 2015
×
Flag on the Play? Recent Disclosure of NFL Player’s Medical Information Sparks Allegations of Privacy Violations
Details
Jul 17, 2015
×
Monitoring the Mayor – B.C. Mayor alleges that computer monitoring violated his privacy
Details
May 21, 2015
×
Green Eggs And Spam: The Surprising Side Dish to Canada’s Anti-Spam Law that May Catch Software Businesses Off Guard
Details
Dec 2, 2014
×
Subscribe for updates
Get updates delivered right to your inbox. You can unsubscribe at any time.
By clicking “Accept All Cookies”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. Cookie Policy
Manage consent
Privacy Overview
This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.